{"id":"CVE-2025-59172","title":"Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.","summary":"Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.","severity":"none","cwe":["CWE-78"],"published":"2026-07-27","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-59172","references":[{"url":"https://www.ericsson.com/en/about-us/security/psirt/security-bulletin-pcc-july-2026","label":"85b1779b-6ecd-4f52-bcc5-73eac4659dcf"}],"tags":["nvd"],"epss":0.00284,"epssPercentile":0.18792,"ingestedAt":"2026-09-29T19:44:04.110Z","slug":"CVE-2025-59172","body":"## Overview\n\nEricsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}